Suspicious
Suspect

dd14398f6e74e048b0f0559bb66244a4

PE Executable
MD5: dd14398f6e74e048b0f0559bb66244a4
Size: 878.59 KB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
Symbol Obfuscation Score Very high
MD5 dd14398f6e74e048b0f0559bb66244a4
Sha1 16fc3feaa8ac81ac4ab5c716a45ac0a8d4572b26
Sha256 3bccecdca2ce3415df0774388ee45110c85073ea0f5e6b7ea8b00a6a1e334336
Sha384 e99512271cb01f1ae124c6189e7f68eee1830f1871e08a71456fb7ef8fb110705c21a96f90ffbabb9edf7825721d956b
Sha512 f9f8127f92420e135d370222d73cba894074c69931230e1aaafc139d31a5ac1ee6f7533cf70f02c588e05821dc39d1c1441097ed73838a0c4e52ab50bfcd772b
SSDeep 12288:OIZMMy2S2byNI/aBbBz6jDXBwHxkV5HQTh6LoOPtXmZXddp7Dux1xg4I7Oni:TZMPL2bEBdz+Bia3UoLZVOXh7K/Kwni
TLSH 4A1522D4D784C9A0CD2F2C34C828916116B2BE3355A3EB267A9D36C8567B3CD50DAF4B
PeID
.NET executableMicrosoft Visual C# / Basic .NETMicrosoft Visual C# / Basic.NET / MS Visual Basic 2005 - ASL Microsoft Visual C# v7.0 / Basic .NETMicrosoft Visual C++ v6.0 DLLMicrosoft Visual Studio .NET
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0-preview.png
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Module Name
server1.exe
Full Name
server1.exe
EntryPoint
System.Void _8D4066403D7A4EF1_::_90B882D1056C4490_()
Scope Name
server1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
server1
Assembly Version
1.2.3.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
12
Main Method
System.Void _8D4066403D7A4EF1_::_90B882D1056C4490_()
Main IL Instruction Count
75
Main IL
nop <null>
ldc.i4 277368439
stloc.3 <null>
ldloc.3 <null>
not <null>
neg <null>
neg <null>
ldc.i4 349976215
add <null>
dup <null>
stloc.2 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br IL_00F8: ret
call System.Object _8D4066403D7A4EF1_::_0A8E42A5A0AA4286_()
stloc.1 <null>
ldloc.1 <null>
ldsfld System.Byte[] _8D4066403D7A4EF1_::_56E906751EE848A5_
call System.Object _8D4066403D7A4EF1_::_5449E2E7D1764DF9_()
call System.Object _8D4066403D7A4EF1_::_44B573335BA5436E_(System.Object)
call System.String _8D4066403D7A4EF1_::_3921E98C3F91493A_(System.Object)
call System.Boolean _8D4066403D7A4EF1_::_B9086DE7594846FC_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 404635272
stloc.s V_7
ldloc.2 <null>
ldc.i4 -611624
mul <null>
ldloc.s V_7
xor <null>
br.s IL_0006: stloc.3
ldsfld System.String _8D4066403D7A4EF1_::_0F379445F4A34CB5_
call System.Byte[] _8D4066403D7A4EF1_::_2857504620DD45CB_(System.String)
stsfld System.Byte[] _8D4066403D7A4EF1_::_56E906751EE848A5_
ldc.i4 1624345317
stloc.s V_5
ldloc.2 <null>
ldc.i4 -95129
mul <null>
ldloc.s V_5
xor <null>
br IL_0006: stloc.3
call System.Object _8D4066403D7A4EF1_::_1121C58A303B4525_()
stloc.0 <null>
ldloc.0 <null>
ldsfld System.Byte[] _8D4066403D7A4EF1_::_56E906751EE848A5_
call System.Object _8D4066403D7A4EF1_::_5449E2E7D1764DF9_()
call System.Object _8D4066403D7A4EF1_::_44B573335BA5436E_(System.Object)
call System.String _8D4066403D7A4EF1_::_3921E98C3F91493A_(System.Object)
call System.Boolean _8D4066403D7A4EF1_::_BEAFCF960BDB4633_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 790727954
stloc.s V_6
ldloc.2 <null>
ldc.i4 -135633
mul <null>
ldloc.s V_6
xor <null>
br IL_0006: stloc.3
call System.String _8D4066403D7A4EF1_::_ABD9C581B6284D22_()
ldc.i4 2038563450
br.s IL_00D3: call System.String <Module>::_269EC7D6A22F4415_<System.String>(System.IntPtr)
call System.String <Module>::_269EC7D6A22F4415_<System.String>(System.IntPtr)
call System.String _8D4066403D7A4EF1_::_FDDA6C785E2D4199_(System.String,System.String)
stsfld System.String _8D4066403D7A4EF1_::_0F379445F4A34CB5_
ldc.i4 1176578493
stloc.s V_4
ldloc.2 <null>
ldc.i4 -316118
mul <null>
ldloc.s V_4
xor <null>
br IL_0006: stloc.3
ret <null>
Module Name
server1.exe
Full Name
server1.exe
EntryPoint
System.Void _8D4066403D7A4EF1_::_90B882D1056C4490_()
Scope Name
server1.exe
Scope Type
ModuleDef
Kind
Windows
Runtime Version
v4.0.30319
Tables Header Version
512
WinMD Version
<null>
Assembly Name
server1
Assembly Version
1.2.3.9
Assembly Culture
<null>
Has PublicKey
False
PublicKey Token
<null>
Target Framework
.NETFramework,Version=v4.8
Total Strings
12
Main Method
System.Void _8D4066403D7A4EF1_::_90B882D1056C4490_()
Main IL Instruction Count
75
Main IL
nop <null>
ldc.i4 277368439
stloc.3 <null>
ldloc.3 <null>
not <null>
neg <null>
neg <null>
ldc.i4 349976215
add <null>
dup <null>
stloc.2 <null>
ldc.i4.6 <null>
rem.un <null>
switch dnlib.DotNet.Emit.Instruction[]
br IL_00F8: ret
call System.Object _8D4066403D7A4EF1_::_0A8E42A5A0AA4286_()
stloc.1 <null>
ldloc.1 <null>
ldsfld System.Byte[] _8D4066403D7A4EF1_::_56E906751EE848A5_
call System.Object _8D4066403D7A4EF1_::_5449E2E7D1764DF9_()
call System.Object _8D4066403D7A4EF1_::_44B573335BA5436E_(System.Object)
call System.String _8D4066403D7A4EF1_::_3921E98C3F91493A_(System.Object)
call System.Boolean _8D4066403D7A4EF1_::_B9086DE7594846FC_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 404635272
stloc.s V_7
ldloc.2 <null>
ldc.i4 -611624
mul <null>
ldloc.s V_7
xor <null>
br.s IL_0006: stloc.3
ldsfld System.String _8D4066403D7A4EF1_::_0F379445F4A34CB5_
call System.Byte[] _8D4066403D7A4EF1_::_2857504620DD45CB_(System.String)
stsfld System.Byte[] _8D4066403D7A4EF1_::_56E906751EE848A5_
ldc.i4 1624345317
stloc.s V_5
ldloc.2 <null>
ldc.i4 -95129
mul <null>
ldloc.s V_5
xor <null>
br IL_0006: stloc.3
call System.Object _8D4066403D7A4EF1_::_1121C58A303B4525_()
stloc.0 <null>
ldloc.0 <null>
ldsfld System.Byte[] _8D4066403D7A4EF1_::_56E906751EE848A5_
call System.Object _8D4066403D7A4EF1_::_5449E2E7D1764DF9_()
call System.Object _8D4066403D7A4EF1_::_44B573335BA5436E_(System.Object)
call System.String _8D4066403D7A4EF1_::_3921E98C3F91493A_(System.Object)
call System.Boolean _8D4066403D7A4EF1_::_BEAFCF960BDB4633_(System.Object,System.Byte[],System.String)
pop <null>
ldc.i4 790727954
stloc.s V_6
ldloc.2 <null>
ldc.i4 -135633
mul <null>
ldloc.s V_6
xor <null>
br IL_0006: stloc.3
call System.String _8D4066403D7A4EF1_::_ABD9C581B6284D22_()
ldc.i4 2038563450
br.s IL_00D3: call System.String <Module>::_269EC7D6A22F4415_<System.String>(System.IntPtr)
call System.String <Module>::_269EC7D6A22F4415_<System.String>(System.IntPtr)
call System.String _8D4066403D7A4EF1_::_FDDA6C785E2D4199_(System.String,System.String)
stsfld System.String _8D4066403D7A4EF1_::_0F379445F4A34CB5_
ldc.i4 1176578493
stloc.s V_4
ldloc.2 <null>
ldc.i4 -316118
mul <null>
ldloc.s V_4
xor <null>
br IL_0006: stloc.3
ret <null>
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rsrc
.reloc
Resources
RT_ICON
ID:0001
ID:0
ID:0002
ID:0
ID:0003
ID:0
ID:0004
ID:0
ID:0005
ID:0
ID:0006
ID:0
ID:0007
ID:0
ID:0-preview.png
ID:0008
ID:0
ID:0009
ID:0
ID:000A
ID:0
RT_GROUP_CURSOR4
ID:7F00
ID:0
RT_VERSION
ID:0001
ID:0
RT_MANIFEST
ID:0001
ID:0
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙